News: 1630473364

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Indonesian authorities probe million-record leak from national COVID app

(2021/09/01)


Indonesia's Ministry of Communications and Informatics is investigating a leak of over a million records from the nation's COVID-19 quarantine management app.

News of the leak was [1]revealed on August 30th by security review site vpnMentor, which wrote that its research team discovered exposed databases generated by [2]eHAC , an app that is mandatory for use by travellers moving into and out of Indonesia, or within its borders.

vpnMentor says its researchers found the data by using "large-scale web scanners to search for unsecured data stores containing information that shouldn't be exposed".

[3]

The eHAC data was "completely unsecured and unencrypted," and when accessing it – using just a browser – the firm's researchers were able to "manipulate the URL search criteria into exposing schemata from a single index at any time".

[4]

[5]

The site's researchers wrote that they were able to access personally identifiable information, travel information, medical records, and COVID-19 status. Some records included national identity numbers. Others named hospital staff who worked with eHAC users – across 226 hospitals.

eHAC users in government also had their personal information exposed.

[6]

The Ministry [7]acknowledged allegations of the leak, and stated that it and the Ministry of Health have opened an investigation.

[8]Tencent Cloud opens first Indonesian data center

[9]Please stop leaking your own personal data online, Indonesia's COVID-19 taskforce tells citizens

[10]Imagine Amazon, Uber and PayPal merging. Indonesia's rough equivalents are probably doing it

Local media suggest a Health Ministry official has advised users to upgrade to a more recent version of eHAC, as the leak only impacts a version of the app that was discontinued in early July 2021. That advice has been interpreted as acknowledgement that older versions of the app employed problematic security controls.

vpnMentor warns of all sorts of unpleasant things that could befall those whose personally identifiable information was exposed in the leak. Happily, there's no indication the exposed trove has been accessed or abused. Yet.

The leak is Indonesia's second health data mess in recent months, after the May 2021 [11]information breach at the national health insurance scheme . ®

Get our [12]Tech Resources



[1] https://www.vpnmentor.com/blog/report-ehac-indonesia-leak/

[2] https://play.google.com/store/apps/details?id=com.kemenkes.inahac&hl=en_AU&gl=US

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YS9PZZ-g3mp08uefu7DrEQAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YS9PZZ-g3mp08uefu7DrEQAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YS9PZZ-g3mp08uefu7DrEQAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YS9PZZ-g3mp08uefu7DrEQAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://kominfo.go.id/content/detail/36694/siaran-pers-no-310hmkominfo082021-tentang-pernyataan-kementerian-kominfo-tentang-dugaan-kebocoran-data-pribadi-pada-aplikasi-ehac/0/siaran_pers

[8] https://www.theregister.com/2021/04/13/tencent_cloud_indonesia/

[9] https://www.theregister.com/2021/03/25/indonesia_covid_qr_code/

[10] https://www.theregister.com/2021/03/10/gojek_and_tokopedia_indonesias_answer/

[11] https://www.theregister.com/2021/05/24/indonesia_health_data_breach/

[12] https://whitepapers.theregister.com/



What did they expect?

Anonymous Coward

You call your app e-hac(k) & expect it NOT to get targeted by every script kiddie in the world? In that case please put this new security app called "E-OpenStableDoor" in charge of your horses. What could possibly go wrong? *FacePalmSigh*

Idiots.

IGotOut

How are you supposed flog everyone's data if you give it away free.

What fools these mortals be.
-- Lucius Annaeus Seneca